CVE-2026-2670

Summary

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."

Affected Software

VendorProductVersion RangeStatus
AdvantechWISE-6610-NB1.2.1_20251110affected
AdvantechWISE-6610-NB1.2.4_20260821unaffected
AdvantechWISE-6610-EB1.2.1_20251110affected
AdvantechWISE-6610-EB1.2.4_20260821unaffected
AdvantechWISE-6610-TB1.2.1_20251110affected
AdvantechWISE-6610-TB1.2.4_20260821unaffected
AdvantechWISE-6610-JB1.2.1_20251110affected
AdvantechWISE-6610-JB1.2.4_20260821unaffected
AdvantechWISE-6610-CB1.2.1_20251110affected
AdvantechWISE-6610-CB1.2.4_20260821unaffected
AdvantechWISE-6610-EL-NB1.2.1_20251110affected
AdvantechWISE-6610-EL-NB1.2.4_20260821unaffected
AdvantechWISE-6610-EL-EB1.2.1_20251110affected
AdvantechWISE-6610-EL-EB1.2.4_20260821unaffected
AdvantechWISE-6610-EL-TB1.2.1_20251110affected
AdvantechWISE-6610-EL-TB1.2.4_20260821unaffected
AdvantechWISE-6610-EL-JB1.2.1_20251110affected
AdvantechWISE-6610-EL-JB1.2.4_20260821unaffected
AdvantechWISE-6610-EL-CB1.2.1_20251110affected
AdvantechWISE-6610-EL-CB1.2.4_20260821unaffected
AdvantechWISE-6610P-DEA1.2.1_20251110affected
AdvantechWISE-6610P-DEA1.2.4_20260821unaffected
AdvantechWISE-6610P-DNA1.2.1_20251110affected
AdvantechWISE-6610P-DNA1.2.4_20260821unaffected
AdvantechWISE-6610P-DTA1.2.1_20251110affected
AdvantechWISE-6610P-DTA1.2.4_20260821unaffected

Weaknesses

  • CWE-78: OS Command Injection
  • CWE-77: Command Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

References